APT28 Exploits Microsoft Office Zero-Day CVE-2026-21509 Targeting Ukraine and EU
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
APT28, also known as UAC-0001 or Fancy Bear, is actively exploiting the Microsoft Office zero-day vulnerability CVE-2026-21509. This vulnerability allows attackers to bypass security features in Microsoft Office, and it was disclosed by Microsoft just a week prior to the attacks. CERT-UA reported that the first weaponized document, titled “Consultation_Topics_Ukraine(Final).doc,” was created on January 27 and surfaced publicly on January 29, indicating a rapid response from the attackers.
In addition to targeting Ukrainian government agencies, the campaign has also extended to organizations across the EU. On the same day the weaponized document was identified, CERT-UA noted a phishing campaign impersonating the Ukrhydrometeorological Center, which sent malicious DOC attachments to over 60 recipients in central government bodies.
The attack begins when a user opens the malicious document, which initiates a WebDAV connection to an external server, downloads a shortcut file, and subsequently drops a DLL disguised as a legitimate Windows component. This process allows the attackers to establish persistence through COM hijacking and a scheduled task that restarts explorer.exe.
Once inside, the attackers deploy the COVENANT post-exploitation framework, which enables them to maintain access and control over the compromised systems. They route their traffic through a legitimate cloud storage service, making it harder for defenders to detect malicious activity.
Despite Microsoft releasing patches for the vulnerability, CERT-UA has expressed concerns about the speed of updates among users. They anticipate an increase in cyberattacks exploiting this vulnerability due to the inertia in updating Microsoft Office and implementing recommended protective measures.
- APT28: A Russian cyber espionage group known for targeting government and military organizations.
- CVE-2026-21509: A security feature bypass vulnerability in Microsoft Office that is currently being exploited.
- WebDAV: A protocol used to facilitate file management over the web, which attackers exploit to download malicious files.
- COVENANT: A post-exploitation framework used by attackers to maintain access to compromised systems.
- COM hijacking: A technique used by attackers to gain persistence on a system by manipulating Windows components.
Key Takeaways
- Ensure that Microsoft Office is updated to the latest version to mitigate vulnerabilities.
- Monitor for unusual Filen-related traffic that may indicate exploitation attempts.
- Educate users about the risks of opening unexpected email attachments, even from known contacts.
- Implement security measures to detect and block phishing attempts targeting your organization.
- Regularly review and update incident response plans to address potential zero-day vulnerabilities.
Key Terms & Concepts
- APT28: In this article, APT28 refers to a Russian cyber espionage group known for targeting government and military organizations.
- CVE-2026-21509: CVE-2026-21509 is a security feature bypass vulnerability in Microsoft Office that is currently being exploited.
- WebDAV: WebDAV is a protocol used to facilitate file management over the web, which attackers exploit to download malicious files.
- COVENANT: COVENANT is a post-exploitation framework used by attackers to maintain access to compromised systems.
- COM hijacking: COM hijacking is a technique used by attackers to gain persistence on a system by manipulating Windows components.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.